PT-2018-2687 · Vmware · Vmware Vrealize Log Insight
Published
2018-11-13
·
Updated
2019-10-03
·
CVE-2018-6980
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VMware vRealize Log Insight versions 4.7.x before 4.7.1
VMware vRealize Log Insight versions 4.6.x before 4.6.2
Description
The issue is related to improper authorization in the user registration method. Successful exploitation may allow Admin users with view-only permission to perform certain administrative functions they are not allowed to perform. The vulnerability can be exploited by a remote attacker to gain unauthorized access to protected information.
Recommendations
For versions 4.7.x before 4.7.1, update to version 4.7.1 or later.
For versions 4.6.x before 4.6.2, update to version 4.6.2 or later.
Fix
Improper Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vmware Vrealize Log Insight